Project

General

Profile

Bug #19289

radosgw/swift emulate split read/write acls?

Added by Marcus Watts 5 months ago. Updated about 1 month ago.

Status:
Pending Backport
Priority:
Normal
Assignee:
Target version:
-
Start date:
03/16/2017
Due date:
% Done:

0%

Source:
Tags:
Backport:
kraken, jewel
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Release:
Needs Doc:
No

Description

With ceph radosgw/swift; setting just the read or write acl clears the other. Unless that behavior is specifically desired, it's currently necessary to set both "-r" and "-w" (on the swift command) at the same time. The swift documentation strongly suggests that is not the case with native swift.

ceph stores just one combined read/write acl, and if either of -r -w was specified, re-initializes this acl before applying the changes. We could emulate swift's behavior more closely by looking to to see if one of -r -w was not specified, and if so, filtering the appropriate bits of the old acl into the new acl.


Related issues

Copied to rgw - Backport #20586: kraken: radosgw/swift emulate split read/write acls? New
Copied to rgw - Backport #20587: jewel: radosgw/swift emulate split read/write acls? New

History

#1 Updated by Marcus Watts 5 months ago

  • Subject changed from radosgw to radosgw/swift emulate split read/write acls?

#2 Updated by Marcus Watts 5 months ago

I've tried this out with swift (ocata). It definitely allows you to just update -r or -w acls separately.

#3 Updated by Yehuda Sadeh 5 months ago

  • Assignee set to Marcus Watts

#4 Updated by Marcus Watts 4 months ago

I've created
https://github.com/ceph/ceph/pull/14499
which has a possible fix for this problem.

#5 Updated by Radoslaw Zarzynski 4 months ago

  • Status changed from New to Need Review
  • Backport set to kraken

#6 Updated by Ken Dreyer 4 months ago

  • Backport changed from kraken to kraken, jewel

#7 Updated by Matt Benjamin about 1 month ago

  • Status changed from Need Review to Pending Backport

#8 Updated by Nathan Cutler about 1 month ago

  • Copied to Backport #20586: kraken: radosgw/swift emulate split read/write acls? added

#9 Updated by Nathan Cutler about 1 month ago

  • Copied to Backport #20587: jewel: radosgw/swift emulate split read/write acls? added

Also available in: Atom PDF